Re: [Rats] TPM background for RIV

Ira McDonald <blueroofmusic@gmail.com> Wed, 26 August 2020 05:07 UTC

Return-Path: <blueroofmusic@gmail.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CFA4B3A0CF6 for <rats@ietfa.amsl.com>; Tue, 25 Aug 2020 22:07:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YzaOQ3p4X6fF for <rats@ietfa.amsl.com>; Tue, 25 Aug 2020 22:07:15 -0700 (PDT)
Received: from mail-vk1-xa2a.google.com (mail-vk1-xa2a.google.com [IPv6:2607:f8b0:4864:20::a2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 303593A0CF8 for <rats@ietf.org>; Tue, 25 Aug 2020 22:07:15 -0700 (PDT)
Received: by mail-vk1-xa2a.google.com with SMTP id i20so144179vkk.2 for <rats@ietf.org>; Tue, 25 Aug 2020 22:07:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=OM/hMybzevwYWeh8jnb4WC0Z0hXtQc+os5tFf0lFybI=; b=Lc3e8xM9ORta64cNdZG5hJKf7ouUSXk31Zlue8OkTv4eVgBKShojHYfe99UOAM/y0o 05MWuehT9ME3dqcu2//WVPRHUjSZmHQg8v2R7ydpN2jxPxOKmAjd9V0/ZpxbOz+IDs0Y /zdgeYAp5hsejoZhLajr8yGok7ixYd2QA8vF5G/CTHayIHEijd9QZWzKN/cyp/YEpELd OPRQykEwk5DPcMICU8S8DmsL9Ye2RPcWAXbbyuDIHOv+5w+lsf2HMzTRgb8agqTgkgN7 fHx+ez9MMFIrU0EgwjGMakpCIWUkByQqmNHf4pU/DO5eTQ3odnH9jvlMEXbo6P8ApMTt qTfQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=OM/hMybzevwYWeh8jnb4WC0Z0hXtQc+os5tFf0lFybI=; b=KX5nwOrtEb7g2NMYjoJbJYi8hLf7Y9BDoB5pVBuLwFtyrbK9PbLovBfNeu7R6564eu ASp6w2xzAj5hYUE+v3GQI6QblM8BF7MpsWg9nqUb7i525UIHQmOuNWFjIZsiilIdEMPq jCp0lVbeMA/TWy0da0uMMnUthphkv4p9dTrvFfiRvu3jEhlBOUj+voA/a1n8i4bGJhM+ 284I9nSaR0p/YZVihWgaErwk+y+iPH3e1Q5qMXoyFS7OxE5L5w46/fPa2hsYxB5W1jG9 PINsoHipcNKYVtAcb8Wy10ukmty1Bxru5m2akvf25d88N3OhjCBFz41wwXbvygyOUsi0 IT6g==
X-Gm-Message-State: AOAM533t8koxjZ/UvbshOGfKfk8X5PKodrdQJvN7oMin+HdGPCCxEteR x1P9UfaAhT/DlmimvqLbaFZLjf+MFQ2fhJDboKKrnoeU
X-Google-Smtp-Source: ABdhPJxLzpGqg9rFIopI9izKGVvOb5wzJprm1DnmaFiJF4uaFy7Xsgvd+jmM6m4HTdM9YeRwR38nnMnKQ5+RXOMmsZM=
X-Received: by 2002:a1f:b6d4:: with SMTP id g203mr7919251vkf.2.1598418434168; Tue, 25 Aug 2020 22:07:14 -0700 (PDT)
MIME-Version: 1.0
References: <DM6PR05MB6889971FB32A359EFFF85D21BA570@DM6PR05MB6889.namprd05.prod.outlook.com> <CAN40gSuS_5skTXE-g1UpeaqO2Ms-QXSG2Jhs7npXf8MgBV001g@mail.gmail.com> <19865.1598394565@localhost>
In-Reply-To: <19865.1598394565@localhost>
From: Ira McDonald <blueroofmusic@gmail.com>
Date: Wed, 26 Aug 2020 01:07:02 -0400
Message-ID: <CAN40gSvibdR2S3Q9KzyU2=6Q8-6_WHdRRj5S5tMGRUAJCSvxUg@mail.gmail.com>
To: Michael Richardson <mcr@sandelman.ca>
Cc: "rats@ietf.org" <rats@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000f89cc005adc0ca36"
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/IJbrpBIeO2jzPOAu2L6andXqWnk>
Subject: Re: [Rats] TPM background for RIV
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2020 05:07:17 -0000

Hi Michael,

Sorry for the confusion.

No, the MCP doesn't forbid PCR8-PCR15, but it doesn't prescribe
their usage either.  No impact on RIV for network equipment.  I was
merely noting that TPM 2.0 Library is largely silent on specifics of
PCR usage.  And there is presently no TPM 2.0 profile for network
equipment.

Cheers,
- Ira



*Ira McDonald (Musician / Software Architect)Co-Chair - TCG Trusted
Mobility Solutions WG*

*Co-Chair - TCG Metadata Access Protocol SG*








*Chair - Linux Foundation Open Printing WGSecretary - IEEE-ISTO Printer
Working GroupCo-Chair - IEEE-ISTO PWG Internet Printing Protocol WGIETF
Designated Expert - IPP & Printer MIBBlue Roof Music / High North
Inchttp://sites.google.com/site/blueroofmusic
<http://sites.google.com/site/blueroofmusic>http://sites.google.com/site/highnorthinc
<http://sites.google.com/site/highnorthinc>mailto: blueroofmusic@gmail.com
<blueroofmusic@gmail.com>(permanent) PO Box 221  Grand Marais, MI 49839
906-494-2434*


On Tue, Aug 25, 2020 at 6:29 PM Michael Richardson <mcr@sandelman.ca> wrote:

> Ira McDonald <blueroofmusic@gmail.com> wrote:
>     > Small note:  Although you say each TPM has at least 16 PCRs, in fact
> the
>     > TPM 2.0 Mobile Common Profile
>     > (2015) only requires the implementation of one SHA-256 bank of 8
> PCRs (a
>     > SHA-1 bank is prohibited here).
>     > That design choice was made to avoid the squabbles over the
> inconsistent
>     > usage of PCR8 through PCR15
>     > across various TPM 2.0 profiles.
>
> I just want to understand.
> TPM 2 mobile, only requires PCR0-7.  It doesn't forbid PCR8->15 though?
> Do devices tend to implement them all?  Or?
>
> So what do the profiles do now?
>
> What is the impact on RIV?
>
> --
> ]               Never tell me the odds!                 | ipv6 mesh
> networks [
> ]   Michael Richardson, Sandelman Software Works        |    IoT
> architect   [
> ]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on
> rails    [
>
>